Connecting Meta the safe way: a read-only System User token

Most tools ask for a Meta login or a token with management permissions. That means a leaked token could pause campaigns, drain budgets, or remove people from your Business Manager. We think that’s an unacceptable trade for a reporting tool — so ROASTED is built around a read-only System User token.

Why a System User

A System User is a non-human identity inside your Business Manager. It has three properties that matter here:

  • Its token never expires — no 60-day re-login dance.
  • It only sees the ad accounts you explicitly assign to it.
  • With assets assigned as View performance, the platform itself rejects every write — renaming, budget changes, member removal, all of it.

We don’t take Meta’s word for that last point. We ran the full battery against our own token: eleven different write attempts — edit campaign, remove a Business Manager member, create ad accounts, claim assets — and all eleven were rejected by Meta. Numbers in, nothing out.

Setup in four steps

  1. In Business settings → Users → System users, create a system user with Employee access (not Admin).
  2. Assign the ad accounts you want reported, each as View performance only.
  3. Generate a token for your app with the ads_read permission.
  4. Paste the token into the Meta Ads card in Connect accounts. Done.

If someone ever stole that token, they could read charts. That’s the whole blast radius — and that’s the point.